Uploaded August 2026 | Updated September 2026, 2 weeks ago
Opening an AWS security group for convenience can create unintended exposure. A common example is allowing access to a database without going through a bastion host, or temporarily opening access while working remotely.
The word “temporary” doesn't make an overly broad rule safe. Matt Lea points to defense in depth: keeping systems in private subnets can provide another barrier even when a firewall or security-group rule is misconfigured.
How many layers of protection should sensitive infrastructure have before one bad configuration stops being catastrophic?
Subscribe to our podcasts: securityweekly.com/subscribe
#AWS #CloudSecurity #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec
Opening an AWS security group for convenience can create unintended exposure. A common example is allowing access to a database without going through a bastion host, or temporarily opening access while working remotely.
The word “temporary” doesn't make an overly broad rule safe. Matt Lea points to defense in depth: keeping systems in private subnets can provide another barrier even when a firewall or security-group rule is misconfigured.
How many layers of protection should sensitive infrastructure have before one bad configuration stops being catastrophic?
Subscribe to our podcasts: securityweekly.com/subscribe
#AWS #CloudSecurity #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec










